Timing budget
Start from the application's timeout, not the access point's roam time. The budget is the longest outage the connection survives; the wireless design has to hold the worst case inside it.
This calculator runs in your browser and keeps its inputs in the link, so you can share a result. Read the timing budget guide for the reasoning behind each formula.
The budget
Longest outage the connection tolerates
40 ms
RPI x (timeout multiplier + network delay multiplier): Input RPI 10ms, Timeout multiplier 2, Network delay multiplier 200%.
In plain words
This connection faults if it goes 40 ms without valid data. That is the whole allowance for any gap the network causes: a roam, a scan, a rekey, or retries queued behind a large transfer.
Part of it is already spent before the radio is involved: the producer's interval, transport across switches and access points, and the receiver's processing. Measure that share; what remains is the wireless budget.
Fits only some of the time: 802.11r fast BSS transition. A design has to hold the worst case.
Overruns even at the bottom of its published range: PSK four-way handshake (no fast roaming), Vendor fast-roam and make-before-break schemes (vendor claim).
This is a safety connection. The timing belongs to the machine builder's risk assessment; this tool only shows what the network has to hold.
Does a roam fit?
| CIP Safety input connection (budget) | 40 ms | Budget |
|---|---|---|
| PSK four-way handshake (no fast roaming) | 55 ms to 520 ms | Overruns |
| 802.11r fast BSS transition | 15 ms to 90 ms | May overrun |
| Vendor fast-roam and make-before-break schemes (vendor claim) | 63 ms to 150 ms | Overruns |
Typical values, measure your own. Your client, its driver, your security setup, and your channel plan decide the real number. A roam that fits on average but not in the worst case still stops the machine.
Where these ranges come from
- Full 802.1X reauthentication. No range is drawn because the published figures measure different things and disagree. A university testbed measured full EAP-TLS reauthentication at about 1.1 s on average across 90 roams, on 802.11b hardware from around 2003. A thesis measured the PEAP exchange alone, from the first EAP message to the RADIUS accept, at 63 to 113 ms with the RADIUS server on the same lab network; that excludes the scan and the four-way handshake. One vendor's wireless phone guide claims 300 ms for a WPA2-Enterprise roam, with no test conditions stated. Apple says the full EAP exchange can take several seconds depending on the authentication infrastructure, and a jointly published industrial Ethernet design guide calls a periodic full reauthentication a sub-second reconvergence that can still cause industrial application timeouts. Your EAP method and RADIUS path decide the number, so measure your own. University of Maryland (DRUM repository), Virginia Tech (VTechWorks), vendor documentation, Apple (Apple Platform Deployment), Rockwell Automation
- PSK four-way handshake (no fast roaming). The bounds come from one industrial lab study, and a bachelor thesis lands inside them. In the lab study, an Intel Wi-Fi 6 client on WPA2-PSK, carried by an AMR between enterprise access points, lost data for about 55 ms during the handover itself and about 520 ms when the roam included a full channel scan. The 2026 bachelor thesis measured ping loss on clients roaming without FT: 75 to 205 ms on a Linux laptop, 150 to 450 ms on a Windows laptop, and about 110 ms on an Android phone. Outliers run past the range: the same thesis recorded about 5.2 s on an iPhone on 2.4 GHz. One vendor's wireless phone guide claims 150 ms for a WPA2-Personal roam, with no test conditions stated. WPA3-SAE adds its own exchange: one small study logged 22 to 247 ms for SAE against 9 to 45 ms for WPA2-PSK on the same access points, without defining that as data outage. Aalborg University (pre-print of European Wireless 2021, VDE), VŠB Technical University of Ostrava (DSpace), vendor documentation, Buletin Poltanesa 26(1), Politeknik Pertanian Negeri Samarinda
- PMK caching and opportunistic key caching. No range is drawn because only one measurement was found. A university testbed that pushed keys to neighboring access points before the client arrived cut re-authentication from about 1.1 s to 25 ms on average (its figure labels the average 50 ms), but it used a simplified two-way handshake on 802.11b hardware from around 2003. No measurement of OKC or PMKID caching on current clients was found. Client vendors describe both only as skipping the full EAP exchange, and PMKID caching helps only when the client returns to an AP that already holds its key, so test your own clients. University of Maryland (DRUM repository), Apple (Apple Platform Deployment), Microsoft Learn
- 802.11r fast BSS transition. Both measurements are FT over PSK, on phones and a Linux client. A 2026 bachelor thesis measured 15 to 90 ms of ping loss for FT roams on two Android phones; at the finest 10 ms sampling one phone lost 15 to 25 ms and the other 55 to 65 ms. An industrial lab study found that FT removed the roughly 6 ms four-way handshake from a handover of about 55 ms on an Intel Linux client, so the mean barely moved, though worst-case latency under load fell. No measured FT roam over 802.1X was found, which is the case where FT avoids a full EAP exchange. One vendor's wireless phone guide claims under 100 ms, with no test conditions stated. Support varies: Windows 10 supports FT only over 802.1X, and in the same thesis FT was absent from two laptops' captures and could not be confirmed on an iPhone, so confirm FT per client before you count on it. VŠB Technical University of Ostrava (DSpace), Aalborg University (pre-print of European Wireless 2021, VDE), vendor documentation, Microsoft Learn, Apple (Apple Platform Deployment)
- Vendor fast-roam and make-before-break schemes. Vendor claims, not independent measurements, and they span a wide range: a jointly published industrial Ethernet design guide measured 63 to 97 ms maximum application convergence for one vendor's proprietary fast roaming at 5 to 100 mph, and an industrial wireless vendor states an average under 150 ms for its fast roaming in optimized conditions with WPA2-PSK. Another vendor claims make-before-break handoffs with zero packet loss but publishes no time, so that claim is not drawn. vendor documentation, Rockwell Automation, vendor documentation
- Wi-Fi 7 multi-link operation. Not an inter-AP roam: in 802.11be the APs of one AP MLD are co-located on the same hardware, so MLO adds link redundancy and load balancing within one AP, a move to another AP is still a BSS transition, and no source found measures anything comparable to a roam. arXiv (2303.10442v3), Wi-Fi Alliance
- 802.11bn seamless mobility domain. Draft only and not available in OT clients: 802.11bn (Wi-Fi 8) targets 25 percent less MPDU loss, especially for transitions between BSSs, and published research proposes a mobility domain of APs affiliated with one extended MLD, but the amendment is at draft stage with approval projected for May 2028 and no source measures a roam time. IEEE 802.11 Working Group, arXiv (2303.10442v3)
Not drawn because no comparable range is published: Full 802.1X reauthentication, PMK caching and opportunistic key caching, Wi-Fi 7 multi-link operation, 802.11bn seamless mobility domain.
Time is distance
Optional. For a moving vehicle, every millisecond of budget is distance traveled before the stop begins.